A hardened, deterministic control baseline for AI coding agents — enforce the guardrails on every endpoint, capture tamper-evident evidence, and map it to your compliance obligations. Built for regulated environments.
These tools read local context, run shell commands under the developer's privileges, and pull in external content. Without enforceable controls, adoption stalls in risk review — or gets waved through.
Commands run with the developer's full local permissions.
Agents can reach .env, SSH keys, and cloud creds.
Repo files, MCP and web content can hijack the agent.
Unbounded network access can move code and data out.
Unreviewed installs and pipe-to-shell vectors.
No evidence the controls worked, or that they map to obligations.
A control plane you manage, with enforcement that runs locally on every endpoint — working even offline. It can't be silently weakened: any tampering breaks the evidence chain.
Managed settings, pre/post-execution hooks and a sandbox block dangerous commands, secrets, protected paths, unapproved egress and MCP — before they run. Denials are explained at the terminal, with an audit-logged exception path for legitimate work.
Every decision is captured as a redacted, hash-chained audit record and forwarded to your SIEM. Code and secrets never leave the endpoint. Edit one byte and the chain breaks.
See a sample evidence record →Control coverage mapped to APRA CPS 230/234, SOC 2 and ISO 27001 — with an audit-ready evidence pack your risk owner can sign off.
Settings and hooks ship free with the agent. What doesn't: a validated thirty-control baseline, adversarial tests proving each control blocks what it claims, and independent evidence mapped to your obligations.
Non-overridable, enterprise-owned baseline delivered via MDM.
Pre/post-execution enforcement — not model judgement.
Command, path, egress and MCP rules as a single source of truth.
Redacted, tamper-evident audit trail, SIEM-ready.
Prove every control blocks what it claims — and detect drift.
Control coverage to CPS 230/234, SOC 2, ISO 27001.
OS-level isolation for shell and child processes where supported.
Re-validate after every agent version or model change.
From lab to fleet — gated rollout, evidence at every step.
Get a regulated rollout approved, then scale to a fleet subscription. Pilot fees credit against an annual plan.
Toren deploys through your existing MDM to macOS, Windows and Linux endpoints. [CONFIRM: exact OS and MDM coverage before publishing]
Yes. All enforcement runs locally on the endpoint. Evidence records queue locally and forward to your SIEM when connectivity returns. [CONFIRM: queueing behaviour]
A one-line explanation at the terminal naming the control that fired. Legitimate work has an audit-logged exception path — denials are designed to be rare, explained and appealable.
Redacted, hash-chained evidence records only. Code, file contents and secrets never leave the machine.
Drift detection re-runs the adversarial test suite against the new version and flags any control regressions before wider rollout.
See the controls enforce live, and the evidence prove it. Ten minutes.